Critical Honeywell CCTV Vulnerability Allows Unauthorized Access
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued a warning regarding a critical vulnerability affecting multiple Honeywell CCTV products. This flaw allows unauthorized access to camera feeds and potential account hijacking, posing a significant risk to security infrastructure.
Vulnerability Details
Discovered by researcher Souvik Kanda and assigned the identifier CVE-2026-1670, the vulnerability is categorized as a “missing authentication for critical function.” CISA has given it a critical severity score of 9.8 out of 10, highlighting the severity of the risk. BleepingComputer first reported on the issue.
The vulnerability enables an unauthenticated attacker to modify the recovery email address associated with a device account. This allows attackers to take control of accounts and gain unauthorized access to live and recorded camera feeds.
According to CISA, the vulnerability stems from an exposed, unauthenticated API endpoint. “The affected product is vulnerable to an unauthenticated API endpoint exposure, which may allow an attacker to remotely change the “forgot password” recovery email address,” CISA stated.
Affected Products
The following Honeywell CCTV models are impacted by CVE-2026-1670:
- I-HIB2PI-UL 2MP IP 6.1.22.1216
- SMB NDAA MVO-3 WDR_2MP_32M_PTZ_v2.0
- PTZ WDR 2MP 32M WDR_2MP_32M_PTZ_v2.0
- 25M IPC WDR_2MP_32M_PTZ_v2.0
Impact and Mitigation
Honeywell is a major supplier of security and video surveillance equipment, with its products widely deployed in commercial, industrial, and critical infrastructure settings. Many of its cameras are NDAA-compliant, making them suitable for use by U.S. Government agencies and federal contractors. The affected models are typically used in small to medium-sized businesses, offices, and warehouses, including some critical facilities.
As of February 17, 2026, CISA reports no known public exploitation of this vulnerability. However, the agency recommends taking the following steps to minimize risk:
- Minimize network exposure of control system devices.
- Isolate devices behind firewalls.
- Use secure remote access methods, such as updated VPN solutions.
While Honeywell has not yet released a public advisory for CVE-2026-1670, users are advised to contact the company’s support team for guidance on patching and mitigation.
Worth a look